Fallos del tipo CWE-522

689 resultados

Credenciais Insuficientemente Protegidas

É quando senhas, tokens ou chaves de acesso são armazenados ou transmitidos sem criptografia adequada, em texto plano ou com proteção fraca. O atacante que ganhar acesso ao código-fonte, banco de dados ou rede consegue ler as credenciais diretamente e entrar no sistema.

Ejemplo

Um desenvolvedor deixa a senha do banco de dados hardcoded em um arquivo .env versionado no Git, ou a API transmite tokens de autenticação por HTTP ao invés de HTTPS. Qualquer pessoa com acesso ao repositório ou monitorando a rede consegue roubar as credenciais.

Cómo mitigar

Use variáveis de ambiente ou gerenciadores de segredos (como HashiCorp Vault, AWS Secrets Manager); nunca versione credenciais. Sempre transmita sobre HTTPS, aplique hash com salt para senhas armazenadas, e implemente expiração e rotação de tokens e chaves.

CVE-2016-9593MEDIUMforeman-debug before version 1.15.0 is vulnerable to a flaw in foreman-debug's logging. An attacker with access to the foreman log file woulEPSS 1.0%CVE-2022-29833MEDIUMInsufficiently Protected Credentials vulnerability in Mitsubishi Electric Corporation GX Works3 versions 1.015R and later allows a remote unEPSS 1.0%CVE-2020-14489MEDIUMOpenClinic GAEPSS 1.0%CVE-2024-47081MEDIUMRequests vulnerable to .netrc credentials leak via malicious URLsEPSS 1.0%CVE-2021-41300CRITICALECOA BAS controller - Insufficiently Protected Credentials-2EPSS 1.0%CVE-2022-45599CRITICALAztech WMB250AC Mesh Routers Firmware Version 016 2020 is vulnerable to PHP Type Juggling in file /var/www/login.php, allows attackers to gaEPSS 1.0%CVE-2024-51984MEDIUMAuthenticated disclosure of external service passwords via pass-back attack affecting multiple models from Brother Industries, Ltd, FUJIFILM Business Innovation, Ricoh, Toshiba Tec, and Konica Minolta, Inc.EPSS 1.0%CVE-2023-31824An issue found in DERICIA Co. Ltd, DELICIA v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access EPSS 1.0%CVE-2023-49280HIGHData leak of password hash through xwiki change requestEPSS 0.9%CVE-2025-25650CRITICALAn issue in the storage of NFC card data in Dorset DG 201 Digital Lock H5_433WBSK_v2.2_220605 allows attackers to produce cloned NFC cards tEPSS 0.9%CVE-2021-23196HIGHFresenius Kabi Agilia Connect Infusion System insufficiently protected credentialsEPSS 0.9%CVE-2021-22798A CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause Sensitive data such as login credentials being exposedEPSS 0.9%CVE-2021-33024LOWPhilips Vue PACS Insufficiently Protected CredentialsEPSS 0.9%CVE-2019-11284MEDIUMReactor Netty authentication leak in redirectsEPSS 0.9%CVE-2021-3528A flaw was found in noobaa-operator in versions before 5.7.0, where internal RPC AuthTokens between the noobaa operator and the noobaa core EPSS 0.9%CVE-2025-27648CRITICALVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.913 Application 20.0.2253 allows Cross Tenant Password Exposure V-20EPSS 0.9%CVE-2025-27650CRITICALVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Private Keys in Docker Overlay V-20EPSS 0.9%CVE-2022-30601CRITICALInsufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow an unauthenticated user to potentially eEPSS 0.9%CVE-2020-36896HIGHQiHang Media Web Digital Signage 3.0.9 Cleartext Credentials DisclosureEPSS 0.9%CVE-2026-47282MEDIUMGitHub Copilot and Visual Studio Code Information Disclosure VulnerabilityEPSS 0.9%